• Private ALPR databases contain billions of timestamped vehicle sightings.
  • Insurers can use the data to verify garaging, vehicle use, and claims.
  • Private networks face far less public scrutiny than police-operated systems.

You probably know if your insurance company is tracking your driving. Maybe you downloaded its app in exchange for a discount, plugged a device into your OBD-II port, or bought a car that quietly reports driving behavior through its connected services. That’s shockingly commonplace today.

But there’s another way companies can learn about your car. Only in this case, you don’t have to download anything, and you don’t have to agree to anything. All you have to do is drive past the right camera.

More: You Can Hide From Flock’s Cameras, If You Turn Your Car Into A Blindfold

Private automated license plate recognition networks are photographing vehicles across America. When they do, they add these encounters into enormous databases containing plates, photographs, locations, and timestamps. That information can then be sold or made available to customers ranging from lenders and repossession companies to insurance companies and law enforcement.

There’s an important difference here, though. Police ALPR networks have generated plenty of controversy lately, but figuring out exactly who is looking at privately held data, and why, can be considerably more difficult than with private ones.

Nine Billion Photos And Counting

 Flock Cameras Are Under Fire, But The Private Networks You Can’t See May Be Worse
Credit: MVTRAC

One of the biggest players is Digital Recognition Network, better known as DRN. Today it’s part of Motorola Solutions, which acquired DRN and its law-enforcement-focused sibling Vigilant Solutions when it bought VaaS International Holdings for $445 million in 2019. At the time, Motorola described the business as providing vehicle-location data to both public-safety and commercial customers through fixed and mobile license plate reader cameras.

The scale is enormous, and we don’t have to rely on DRN’s marketing claims to establish that. A California appeals court recently noted that, as of May 2024, DRN’s system contained more than 9 billion historical license plate images. Those aren’t simply nine billion pictures of license plates.

The court described records containing images of plates and vehicles along with the date, time, and location where each image was captured. DRN sells ALPR hardware, including fixed cameras and mobile systems that can be mounted to vehicles such as tow trucks. One random photograph of your car probably isn’t particularly revealing. Billions of them collectively become something very different.

And DRN isn’t alone in collecting license plates at enormous scale. MVTRAC, which primarily serves auto lenders and the repossession industry, says its network collects more than 500 million new LPR data points every month through a nationwide network of more than 600 recovery affiliates.

Flock Safety represents another model entirely. Their cameras are used by private businesses, neighborhoods, apartment complexes, schools, and other organizations, which have the option of sharing vehicle data with law enforcement.

The companies and their business models aren’t identical, but the broader point is that privately operated cameras are already collecting enormous amounts of data about where vehicles are seen.

Your Insurer Can Use It

 Flock Cameras Are Under Fire, But The Private Networks You Can’t See May Be Worse
Credit: DRN

There’s also no question about whether DRN sells access to its information. A 2015 federal appeals court decision involving DRN described its business remarkably plainly. Cameras mounted on tow trucks and other vehicles automatically photographed vehicles they encountered, recorded GPS coordinates, dates and times, and DRN sold the resulting license plate data to customers including automobile finance and insurance companies.

DRN still openly advertises insurance products built around that information today. One called Garage Aware is designed to determine whether your vehicle is actually kept where you told your insurance company it is. That’s important because insurance rates can vary significantly based on where a car is garaged. And the system gets almost shockingly granular.

DRN’s developer documentation describes “sleep hour sightings” and has the ability to compare these observations with both the address provided by a customer and another location discovered through its data. The system can even incorporate the difference in insurance premiums between ZIP codes.

Another product, Radius Response, uses license plate sightings to determine whether commercial vehicles are regularly operating beyond their declared geographic area. Then there’s Vehicle Sighting Search. DRN advertises that to insurers as a way to “map vehicle movements” to investigate claims, identify suspicious patterns, and enforce policy compliance.

Images can be valuable too. DRN says insurers can examine them for company signage, toolboxes, ladder racks, and trailers that might indicate someone is using a personally insured vehicle commercially. Historical images can also help determine whether damage existed before an insurance claim.

To be clear, there are perfectly legitimate applications for all of this. Someone claiming their Mercedes lives in rural Iowa when it’s actually parked every night in downtown Chicago is withholding information an insurer legitimately uses to calculate risk. The same applies to someone insuring a work truck as a personal vehicle.

The problem is that the technology capable of discovering those deceptions is also capable of revealing much more.

The Database Knows More Than Where You Live

 Flock Cameras Are Under Fire, But The Private Networks You Can’t See May Be Worse
Credit: DRN

Consider what repeated sightings could establish. A vehicle consistently photographed at one location overnight can potentially reveal where its owner lives. Repeated appearances somewhere else during weekdays could suggest where that person works. Other recurring locations could begin revealing routines, relationships, and habits.

If those sound like the same privacy concerns raised about police-operated ALPRs, that’s because they are. The issue is what happens when thousands of perfectly mundane observations are assembled chronologically. Your license plate effectively becomes a persistent identifier.

Unlike location sharing on your phone, you can’t turn it off. In most circumstances, you probably won’t even know the observation happened. And that’s where the private side of this gets particularly interesting.

Less Sunlight

Police ALPR systems can certainly be abused, and recent controversies have provided plenty of reasons to question how they’re being used. But government agencies also operate under forms of accountability that private companies generally don’t.

Depending on the jurisdiction, journalists and citizens can file public-records requests. Departments can establish search policies. Officers can be disciplined for inappropriate use. Legislatures can demand answers. Courts can intervene. Search logs can potentially reveal who accessed information and why.

More: Florida Sheriff Pulls County’s Flock Cameras Over One Detective

None of those safeguards guarantees responsible behavior. We’ve seen plenty of evidence lately that police ALPR systems can be misused. But those guardrails create opportunities for someone outside the system to look inside. A private company’s internal audit log isn’t the same thing as a publicly accessible one.

DRN, for example, does have security policies and controls. The recent California appeals court decision notes that the company requires third parties to sign agreements requiring compliance with applicable laws and that DRN conducts periodic audits of its usage logs. That’s important context. It also doesn’t solve the broader issue.

If you’re curious whether someone searched your license plate in a privately operated commercial database, you can’t simply send the company the equivalent of a Freedom of Information Act request demanding its search history. That leaves an extraordinary amount riding on private companies policing themselves and their customers.

Don’t forget that several of the victims of ALPR misuse and abuse by police only found out because they were granted access to their own ALPR data. Good luck with getting that same transparency out of any private company that leverages ALPR technology. 

What Happens If Someone Gets In?

 Flock Cameras Are Under Fire, But The Private Networks You Can’t See May Be Worse
Credit: DRN

There’s another issue that has nothing to do with an authorized customer deliberately misusing the data. Someone could steal it. That’s not an accusation that DRN’s database has been compromised. We found no evidence of a breach, and DRN says it maintains security procedures designed to prevent unauthorized access.

The problem is more fundamental than any particular company’s cybersecurity. This database exists. Every additional observation potentially makes it more useful, both to legitimate customers and to anyone who shouldn’t have access. A sufficiently large historical ALPR database isn’t just a list of license plates but potentially a partial map of where millions of vehicles have been over time.

Someone who gains unauthorized access doesn’t need every vehicle to have been photographed every mile of every journey for that information to become sensitive. A handful of predictable locations may be enough to establish patterns.

A Surveillance Network You Never Joined

 Flock Cameras Are Under Fire, But The Private Networks You Can’t See May Be Worse
Credit: DRN

Perhaps the strangest thing about private ALPR networks is how little involvement is required from the people whose movements ultimately create the product. Your car just happened to pass a camera.

DRN didn’t respond to a request for comment; its website openly markets vehicle-location intelligence to insurers, lenders and recovery companies, and court records describe the collection and sale of its license plate data for more than a decade.

The harder question is what happens as privately controlled databases containing billions of timestamped vehicle locations continue growing while the public debate remains overwhelmingly focused on cameras operated by police. We’ve spent years asking whether the government should be able to build a database capable of revealing where ordinary people go. But the private sector has been building one too. 

Lead Image: DRN